ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0141×

22 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareWinnti for Windows

Winnti for Windows has the ability to encrypt and compress its payload.

T1027.015
Compression
MalwareWinnti for Windows

Winnti for Windows has the ability to encrypt and compress its payload.

T1036.005
Match Legitimate Resource Name or Location
MalwareWinnti for Windows

A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.

T1057
Process Discovery
MalwareWinnti for Windows

Winnti for Windows can check if the explorer.exe process is responsible for calling its install function.

T1070.004
File Deletion
MalwareWinnti for Windows

Winnti for Windows can delete the DLLs for its various components from a compromised host.

T1070.006
Timestomp
MalwareWinnti for Windows

Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe.

T1071.001
Web Protocols
MalwareWinnti for Windows

Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications.

T1082
System Information Discovery
MalwareWinnti for Windows

Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP.

T1083
File and Directory Discovery
MalwareWinnti for Windows

Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution.

T1090.001
Internal Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of a local proxy.

T1090.002
External Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of an external proxy.

T1095
Non-Application Layer Protocol
MalwareWinnti for Windows

Winnti for Windows can communicate using custom TCP.

T1105
Ingress Tool Transfer
MalwareWinnti for Windows

The Winnti for Windows dropper can place malicious payloads on targeted systems.

T1106
Native API
MalwareWinnti for Windows

Winnti for Windows can use Native API to create a new process and to start services.

T1140
Deobfuscate/Decode Files or Information
MalwareWinnti for Windows

The Winnti for Windows dropper can decrypt and decompresses a data blob.

T1218.011
Rundll32
MalwareWinnti for Windows

The Winnti for Windows installer loads a DLL using rundll32.

T1480.001
Environmental Keying
MalwareWinnti for Windows

The Winnti for Windows dropper component can verify the existence of a single command line parameter and either terminate if it is not found or later use it as a decryption key.

T1543.003
Windows Service
MalwareWinnti for Windows

Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareWinnti for Windows

Winnti for Windows can add a service named wind0ws to the Registry to achieve persistence after reboot.

T1548.002
Bypass User Account Control
MalwareWinnti for Windows

Winnti for Windows can use a variant of the sysprep UAC bypass.

T1569.002
Service Execution
MalwareWinnti for Windows

Winnti for Windows can run as a service using svchost.exe.

T1573.001
Symmetric Cryptography
MalwareWinnti for Windows

Winnti for Windows can XOR encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.